Positive Technologies (dbugs)
| |
|---|
| Product | Positive Technologies vulnerability database (dbugs) |
| Records still shown as active | 1 |
| First contacted | 2026-08-08 |
| Channels tried | dbugs@ |
| Status | Awaiting response |
Records
CVE-2025-15603
| |
|---|
| Authoritative state | REJECTED at cve.org and NVD since 2026-06-18 |
| Withdrawn by | VulDB, the issuing CNA, as a false positive |
| Their entry | PT-2026-24109, published and last updated 2026-03-09 |
| What it displays | An active vulnerability in open-webui, weak WEBUI_SECRET_KEY randomness, CVSS 3.7 Low, annotated "The exploit has been publicly disclosed", with the recommendation to "update to a version of open-webui greater than 0.6.16" |
| Our assessment | CVE-2025-15603 |
The score matches the CNA, so this is a status problem rather than a scoring one: the entry was last updated more than three months before the withdrawal and has not re-synced.
What makes it worse than a stale row is the recommendation. The entry instructs the reader to upgrade in order to remediate an identifier that no longer exists, which turns a data-freshness defect into a maintenance action taken on false grounds.
| Date | Channel | Outcome |
|---|
| 2026-08-08 | dbugs@ | Awaiting response |
See also
This content is for informational purposes only and does not constitute a warranty, guarantee, or contractual commitment. Open WebUI is provided "as is." See your
license for applicable terms.